Microsoft 365

Microsoft 365 security audit checklist for small businesses

What a Microsoft 365 security audit covers, what good looks like in each area, and how to decide between a do-it-yourself review and a professional one.

Published
September 10, 2026
Updated
September 10, 2026
Author
Ashwin C.

A Microsoft 365 security audit is a structured review of how your tenant is configured — identity, email, file sharing, devices, monitoring, recovery, and licensing. The important part is that most of the controls involved are already included in the licenses you pay for. An audit does not buy new protection; it checks that the protection you already own is switched on, scoped correctly, and actually watched.

This checklist follows the areas our Microsoft 365 Security Review & Hardening service examines, based on Microsoft’s current documentation. It is written so you can run a basic pass yourself, or use it to judge a professional review.

1. Identity and sign-in

  • Multi-factor authentication is enforced for every user, not only administrators. In the Entra admin center, the user registration details view shows who has registered and with which method.
  • Legacy authentication (POP, IMAP, SMTP AUTH) is blocked. Security defaults blocks it outright; with Conditional Access, Microsoft publishes a dedicated policy for it. Legacy protocols cannot enforce MFA, which is why they are a common entry point.
  • Security defaults and Conditional Access are not both disabled. If you have Conditional Access licensing, the deliberate choice is usually Conditional Access with security defaults off — not both off. Our MFA guide covers that decision.
  • Conditional Access policies are documented, and none have been left in report-only mode indefinitely. A report-only policy observes, it does not block.
  • Administrative roles are reviewed: how many Global Administrators exist, whether admins use dedicated accounts, and whether each assignment is still needed. Stale admin access is a common finding.

2. Email protection

  • Anti-phishing, Safe Links, and Safe Attachments are applied to all users. Microsoft’s preset security policies are the quickest way to confirm this rather than checking each policy separately.
  • Impersonation protection covers named executives and finance staff, not just the default policy scope.
  • External auto-forwarding is restricted. Attackers add quiet inbox rules to copy mail out; reviewing existing transport and inbox rules is part of the audit, not an optional extra.
  • SPF, DKIM, and DMARC are configured for every sending domain. A DMARC record set to p=none monitors but does not block spoofed mail, so note which policy is actually in place.

3. File sharing and guest access

  • Tenant-level external sharing matches how the business works. Microsoft enables external sharing by default, and site-level settings can be more restrictive than the tenant setting but never looser.
  • Anonymous “Anyone with the link” sharing is a deliberate choice, with link expiry where it is allowed.
  • Guest accounts are reviewed: who invited them, what they can still reach, and which ones are no longer needed. A guest with access to a sensitive site is an open door, even if the link that created it has been forgotten.

4. Devices

  • Devices that access company data are enrolled and have a compliance policy in Intune. A compliance policy only changes anything if Conditional Access actually requires a compliant device.
  • Disk encryption, operating system update status, and endpoint protection reporting are checked for each managed device.
  • Personal and unmanaged devices are either blocked from sensitive content or covered by an app protection policy.

5. Monitoring and audit logging

  • Microsoft Purview audit search is enabled and retention is understood. Audit search is turned on by default for Microsoft 365 organizations; records are retained for 180 days by default for non-E5 licenses (one year for E5-class licenses).
  • Alert policies exist for high-risk activity, such as mass downloads or new external forwarding rules.
  • Sign-in logs are reviewed on a cadence, not only after an incident: failed sign-ins from unusual locations, successful sign-ins that should have been blocked, and any legacy authentication attempts that still get through.

6. Recovery and continuity

  • Account recovery paths are documented, and at least one administrator account is excluded from Conditional Access as a break-glass account — tested, stored safely, and not used daily.
  • Someone can restore deleted mail, OneDrive files, and SharePoint content, and the business knows how long that window is. Microsoft 365 keeps the service running; it is not a backup of your data.
  • Departing staff are offboarded in a fixed order, so access is cut without losing the mailbox or files. Our offboarding checklist covers that sequence.

7. Licensing and Microsoft Secure Score

  • Microsoft Secure Score is used as a starting point, not a target to maximize. It shows recommended actions and where they apply; some suggestions will not suit your licensing or how the business works.
  • Controls that require a higher license tier than you hold are flagged rather than assumed. The audit should tell you what is impossible on your current plans, and what the upgrade would actually buy.

How often should you run a Microsoft 365 security audit?

At least once a year, with identity and sharing settings reviewed more often, because those change fastest. Run a pass after any event that moves accounts or data around: a departure, a migration, a new line-of-business app, a Copilot or Teams rollout, or a client and insurer questionnaire. Configuration drift is normal — the audit exists to catch it on a schedule instead of during an incident.

Doing it yourself or hiring someone

If someone on your team owns Microsoft 365 administration and has a few hours, this checklist will surface the majority of common findings. A professional review makes more sense when no one owns the tenant day to day, when you need evidence for cyber-insurance or a client security questionnaire, or when the fixes could break a workflow and need to be sequenced safely. A review should separate what was observed from what is recommended, and leave you with a written record either way.

Where this fits into a broader review

This checklist covers configuration. It does not cover whether the business could keep operating through an incident, or what an outsider can already see of your public systems. If you want the configuration reviewed with a staged change plan, see Microsoft 365 Security Review & Hardening; a regular cadence afterwards is what Monthly Security Care is for.


Sources

Have a specific situation in mind?

Discuss your needs